Communication authentication method
The described method enhances NFC-based vending machine authentication by generating and combining key data via NFC, ensuring secure transactions without server dependency, thus maintaining convenience and security.
Patent Information
- Application Number
- JP2022032601
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-03
- Publication Date
- 2025-12-03
- Estimated Expiration
- 2042-03-03
AI Technical Summary
Existing NFC communication systems for vending machines require more secure authentication methods to protect payment and data while maintaining convenience.
A communication authentication method involving a communication authentication terminal device that generates and combines key data via NFC with a portable wireless terminal, using a predetermined algorithm to ensure secure authentication without needing a server connection.
Enables secure communication authentication without compromising the convenience of NFC, allowing for simple and efficient installation of the terminal device.
Smart Images

Figure 0007779529000001 
Figure 0007779529000002 
Figure 0007779529000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication authentication method and a communication authentication terminal device in a mutual communication system using NFC. [Background technology]
[0002] A system is known in which communication with a vending machine is established via application software (app) installed on a mobile communication terminal, a product is selected from the app, electronic payment is made, and the product is then received from the vending machine.
[0003] For example, Patent Document 1 discloses a system in which a mobile communication terminal is connected to a food and beverage dispensing device such as a vending machine using a communication means compliant with standards such as Bluetooth or wireless LAN, and the food and beverage desired to be purchased is specified and payment is made on the mobile communication terminal, after which the payment information and information on the food and beverage are detected by the vending machine, and the food and beverage are dispensed.
[0004] Furthermore, Patent Document 2 discloses a system in which a mobile communication terminal and a vending machine communicate and authenticate each other using a communication means compliant with a short-range wireless communication standard such as NFC (Near Field Communication), which enables two-way communication, and then dispense products. In this system, two communication means are used, and the short-range wireless communication means is used to exchange member information and to obtain connection information for the long-distance, high-speed wireless communication means that controls the product dispensing process. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Publication No. 2017-174320 [Patent Document 2] Japanese Patent Application Laid-Open No. 2014-96090 Summary of the Invention [Problem to be solved by the invention]
[0006] NFC has a short communication distance of about 10 cm, making it safer than communication methods with longer communication distances such as Bluetooth, and it is less affected by the external environment, resulting in superior connection stability. It also requires less power, allowing for compact terminals, including peripheral devices. Meanwhile, when authenticating communication between a mobile communication terminal and a communication authentication terminal device installed in a vending machine, such as the one described above, more secure communication authentication is required because payment information and other data are handled.
[0007] The present invention has been made in view of the above circumstances, and its object is to provide a method and a communication authentication terminal device for performing more secure communication authentication in a mutual communication authentication system using NFC, without compromising the convenience of NFC. [Means for solving the problem]
[0008] A method according to the present invention is a method of communication authentication in a mutual communication system using a communication authentication terminal device that is communicatively connected via NFC to a portable wireless terminal that is connected to a server device, wherein the portable wireless terminal receives first key data generated by the server device using a predetermined generation algorithm and connects to the communication authentication terminal device via NFC, the communication authentication terminal device, upon connecting to the portable wireless terminal via NFC, acquires the first key data from a source other than the portable wireless terminal and returns the generated second key data to the portable wireless terminal via NFC, the portable wireless terminal receives the second key data, combines the first key data and the second key data according to a predetermined rule to generate third key data and transmits it to the communication authentication terminal device via NFC, the communication authentication terminal device receives the third key data, combines the first key data acquired from a source other than the portable wireless terminal and the generated second key data according to the predetermined rule, and compares it with the third key data transmitted from the portable wireless terminal to perform communication authentication.
[0009] According to this feature, it is possible to perform more secure communication authentication without compromising the convenience of NFC.
[0010] The above-described method may be characterized in that the first key data is generated and acquired in the communication authentication terminal device using the predetermined algorithm. According to this feature, the communication authentication terminal device does not need to be connected to a server device, so the communication authentication terminal device can be made simple and more secure communication authentication can be performed without compromising the convenience of NFC.
[0011] The above-described method may be characterized in that the portable wireless terminal transmits a token to the server device to perform token authentication, thereby receiving the first key data from the server device. The predetermined algorithm may also be characterized in that it includes processing that reflects the time and / or location of the token authentication. The portable wireless terminal may also be characterized in that it starts installed application software to transmit the token to the server device, and receives the second key data only when it is communicatively connected to the communication authentication terminal device via NFC within a certain period of time after receiving the first key data. This feature enables more secure communication authentication without compromising the convenience of NFC.
[0012] In the above-described method, the second key data may be random number data. The third key data may be generated by combining the first key data and the second key data and converting them into a character string of a predetermined number. The conversion into the character string may be performed using a hash function. This feature enables more secure communication authentication without compromising the convenience of NFC.
[0013] Furthermore, a communication authentication terminal device according to the present invention is a communication authentication terminal device that is communicatively connected via NFC with a portable wireless terminal connected to a server device to form a mutual communication system and perform communication authentication, and when the server device communicatively connects via the NFC to the portable wireless terminal that has received first key data generated by a predetermined generation algorithm, the server device acquires the first key data from a source other than the portable wireless terminal and returns the generated second key data to the portable wireless terminal via the NFC, and when the server device receives via the NFC from the portable wireless terminal third key data that has been generated by combining the first key data and the second key data according to a predetermined rule, the server device combines the first key data acquired from a source other than the portable wireless terminal and the generated second key data according to the predetermined rule and compares it with the third key data transmitted from the portable wireless terminal to perform communication authentication.
[0014] According to this feature, it is possible to perform more secure communication authentication without compromising the convenience of NFC.
[0015] In the above-described invention, the first key data may be generated and acquired using the predetermined algorithm. According to this feature, the communication authentication terminal device does not need to be connected to a server device, so the communication authentication terminal device can be made simple and more secure communication authentication can be performed without compromising the convenience of NFC.
[0016] In the above-described invention, the portable wireless terminal may be characterized in that it transmits a token to the server device to perform token authentication, thereby receiving the first key data from the server device, and the predetermined algorithm includes processing that reflects the time and / or location of the token authentication. Furthermore, the portable wireless terminal may be characterized in that it launches installed application software to transmit the token to the server device, and transmits the second key data only when a communication connection is established via NFC within a certain period of time after receiving the first key data. This feature enables more secure communication authentication without compromising the convenience of NFC.
[0017] In the above invention, the second key data may be random number data. The third key data may be generated by combining the first key data and the second key data and converting them into a character string of a predetermined number. The conversion into the character string may be performed using a hash function. This feature enables more secure communication authentication without compromising the convenience of NFC. [Brief explanation of the drawings]
[0018] [Figure 1] 1 is a block diagram illustrating a method for authenticating communications in one embodiment according to the present invention. [Figure 2] FIG. 1 is a flow diagram illustrating a method for authenticating communications in one embodiment according to the present invention. [Figure 3] FIG. 1 is a flow diagram illustrating a method for authenticating communications in one embodiment according to the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0019] A method of communication authentication in a mutual communication system as a typical example of the present invention will be described below with reference to FIGS.
[0020] As shown in Fig. 1, a communication authentication terminal device 1 is used to perform mutual authentication between the communication authentication terminal device 1, the mobile wireless terminal 2, and a server device 3 via a mobile wireless terminal 2 that is communicatively connected by NFC. Here, the mobile wireless terminal 2 is a terminal that can be connected to the server device 3 via a publicly known line such as an Internet line via an access point, and a smartphone, for example, can be suitably used. The communication authentication terminal device 1 is communicatively connected by NFC to the mobile wireless terminal 2 that is connected to the server device 3, thereby forming a mutual communication system.
[0021] The server device 3 is a dedicated or general-purpose device that holds information about the mobile wireless terminal 2 and is used for the above-mentioned authentication. When the mobile wireless terminal 2 requests authentication for electronic payment or the like using the communication authentication terminal device 1, the server device 3 provides authentication for the connection to the server device 3, and then creates and transmits first key data K1a to the mobile wireless terminal 2. The first key data K1a is generated using a predetermined generation algorithm each time an authentication request is made from the mobile wireless terminal 2. The first key data K1a is generated, for example, reflecting the time when authentication is requested from the mobile wireless terminal 2 and the location of the mobile wireless terminal 2 at that time. can In addition, the first key data K1a is one that does not change over a certain period of time even if the time of generation is shifted, and it can be similar to a one-time password generated using a so-called time stamp method. In this case, it is preferable that the first key data K1a does not change even if the time is shifted by about one minute.
[0022] The mobile wireless terminal 2 has application software installed therein for requesting authentication in the above-mentioned intercommunication system. By starting up the application software and accessing the server device 3, the mobile wireless terminal 2 first requests authentication for connection with the server device 3. It is preferable that this application software be efficiently developed using, for example, an SDK (Software Development Kit). When the mobile wireless terminal 2 is authenticated for connection by the server device 3 as described above, it receives first key data K1a. It is also preferable that the mobile wireless terminal 2 transmit a token when requesting authentication from the server device 3 so that token authentication is performed, as this makes the authentication more secure.
[0023] As described above, the portable wireless terminal 2 can be communicatively connected to the communication authentication terminal device 1 via NFC. When the portable wireless terminal 2 is communicatively connected to the communication authentication terminal device 1, it receives second key data K2 from the communication authentication terminal device 1 and combines this with the first key data K1a received from the server device 3 according to a predetermined rule to generate third key data K3a. The generated third key data K3a is then transmitted to the communication authentication terminal device 1. The generation and transmission of the third key data K3a from this communication connection are performed as a series of operations by the application software described above, following the connection to the server device 3. Note that, since the portable wireless terminal 2 communicates with the communication authentication terminal device 1 via NFC, it is preferable to use, for example, NDEF (NFC Data Exchange Format) as the data format for such communication.
[0024] The communication authentication terminal device 1 is attached to, for example, a vending machine, and can send a signal to the vending machine permitting electronic payment when mutual authentication is achieved in the above-mentioned mutual communication system by a method described below. This signal enables the vending machine to dispense merchandise or digital data, thereby enabling the holder of the portable wireless terminal 2 to purchase the merchandise. The communication authentication terminal device 1 is a device that outputs information indicating that the portable wireless terminal 2 has been authenticated to the outside, and may be used for purposes other than electronic payment. In other words, it may be configured to provide various services after authentication between the above-mentioned mutual communication systems. Furthermore, the communication authentication terminal device 1 operates in card emulation mode during the above-mentioned NFC communication, and can operate with low power consumption because it only needs to maintain minimum functions such as the operation of an internal clock. In other words, the portable wireless terminal 2 communicates via NFC in reader / writer mode.
[0025] The communication authentication terminal device 1 acquires first key data K1b when communication is connected from the mobile wireless terminal 2. This first key data K1b is generated using the same generation algorithm as that used to generate the first key data K1a in the server device 3. In other words, as described above, it is generated to reflect the time when the mobile wireless terminal 2 requests authentication from the server device 3 and the location of the mobile wireless terminal 2 at that time.
[0026] Here, the communication authentication terminal device 1 is connected to the portable wireless terminal 2 via NFC. That is, at this time, the portable wireless terminal 2 is located very close to the communication authentication terminal device 1. Furthermore, as described above, the connection to the server device 3 and the communication connection to the communication authentication terminal device 1 are performed in a series of operations, and the time of connection to the server device 3 and the time of connection to the communication authentication terminal device 1 can be very close to each other. Therefore, by determining that these very close times and places are the same, the first key data K1a generated by the server device 3 and the first key data K1b acquired by the communication authentication terminal device 1 can be made to have the same content.
[0027] For example, the location of the portable wireless terminal 2 can be replaced with the ID number of the communication authentication terminal device 1 or the ID number of a facility such as a vending machine where the device is installed. That is, the server device 3 stores information such as the address of the location where the communication authentication terminal device 1 is installed, in association with the ID number. The location of the portable wireless terminal 2 is then replaced with the ID number from the address or other information, and the individual communication authentication terminal 2 located at the location of the portable wireless terminal 2 is identified by the replaced ID number. The location of the portable wireless terminal 2 can be identified from the built-in GPS or the location of the connected base station. Therefore, the location of the portable wireless terminal 2 can be processed as the same in both the communication authentication terminal 1 and the server device 3.
[0028] Furthermore, the first key data K1a and K1b are generated in the same manner as for one-time passwords in the timestamp system as described above, and the time at which they are generated can also be treated as the same time. For example, after receiving the first key data K1a from the server device 3, if the mobile wireless terminal 2 establishes a communication connection with the communication authentication terminal device 1 within a certain time, the data can be treated as the same time. Therefore, the second key data K2 may be transmitted only when the mobile wireless terminal 2 establishes a communication connection with the communication authentication terminal device 1 within a certain time after receiving the first key data K1a.
[0029] That is, the first key data K1b acquired by the communication authentication terminal device 1 is acquired from a source other than the portable wireless terminal 2, and is the same as the first key data K1a received by the portable wireless terminal 2. For example, the first key data K1b may be generated inside the communication authentication terminal device 1. In this case, the communication authentication terminal device 1 does not need to communicate with the server device 3, which is preferable because it can be easily installed.
[0030] As described above, when a communication connection is made with the mobile wireless terminal 2, the communication authentication terminal device 1 generates second key data K2 and returns it to the mobile wireless terminal 2 via NFC. The communication authentication terminal device 1 also generates third key data K3b by combining the acquired first key data K1b and the generated second key data K2 according to a predetermined rule. Furthermore, the generated third key data K3b is compared with the third key data K3a received from the mobile wireless terminal 2, and if they match, the mobile wireless terminal 2 is authenticated and a message to that effect is output. It is preferable that the second key data K2 be random number data, as this allows for secure authentication.
[0031] The above-mentioned first key data can be generated specifically as follows. For example, when updating the time at one-minute intervals, the communication authentication terminal 1 generates three pieces of first key data K1b based on three times: the current time and one minute before and after. Three pieces of third key data K3b are also generated based on this, and it is sufficient if any one of them matches the third key data K3a received from the portable wireless terminal 2. This means that times with a difference of about one minute can be processed as the same time.
[0032] As described above, the third key data K3a or K3b is generated by combining the first key data K1a or K1b with the second key data K2, but it is preferable that the third key data K3a or K3b is generated by converting it into a predetermined number of character strings and further converted using a hash function. In particular, since a hash function is a one-way function, it makes it difficult to guess the data before conversion, enabling more secure authentication.
[0033] Next, a specific example of the above authentication method will be explained in chronological order.
[0034] 2 and 3, first, the owner of the mobile wireless terminal 2 starts application software for receiving authentication and then receiving services near the communication authentication terminal device 1 that the owner wishes to receive authentication from. Upon starting up, the application software connects to the server device 3 and requests authentication (S1).
[0035] Upon receiving the authentication request, the server device 3 checks the token sent from the mobile wireless terminal 2 to determine whether authentication is possible (S2), and if authentication is not possible (S2: No), it returns a signal to the mobile wireless terminal 2 indicating that authentication has failed. If authentication is possible (S2: Yes), it generates and issues first key data K1a (S3). If the server device 3 fails to issue the first key data K1a (S4: No), it returns a signal to the mobile wireless terminal 2 indicating that issuance has failed and transitions to a standby state (S5). If the server device 3 succeeds in issuing the first key data K1a (S4: Yes), it transmits the first key data K1a to the mobile wireless terminal 2, returns a signal indicating that issuance has succeeded, and transitions to a standby state (S5).
[0036] The portable wireless terminal 2 determines whether the authentication by the server device 3 was successful based on the reception of a signal indicating a failure in authentication or a failure in issuing the first key data K1a, or the reception of the first key data K1a (S6). That is, if the first key data K1a is received, the authentication is deemed successful (S6: Yes), and NFC communication is enabled (S7). Otherwise (S6: No), the application software records the error content as error processing (SE), and the process ends. Meanwhile, the communication authentication terminal device 1 waits for a connection from the portable wireless terminal 2 (S8).
[0037] When the portable wireless terminal 2 receives the first key data K1a, the application software displays a message prompting the user to access the communication authentication terminal device 1. The person carrying the portable wireless terminal 2 follows the message and holds the portable wireless terminal 2 over the communication authentication terminal device 1 to attempt a communication connection (S9).
[0038] In response to this, the communication authentication terminal device 1 confirms whether a communication connection with the portable wireless terminal 2 via NFC has been established (S10). If the communication connection has not been established (S10: No), the process proceeds to the error processing (SE) described above. On the other hand, if the communication connection has been established (S10: Yes), the communication authentication terminal device 1 generates second key data K2 and transmits it to the portable wireless terminal 2 (S11).
[0039] As described above, the communication authentication terminal device 1 acquires the first key data K1b from a source other than the mobile wireless terminal 2, and combines it with the generated second key data K2 according to a predetermined rule to generate the third key data K3b (S12).
[0040] On the other hand, the mobile wireless terminal 2 that has received the second key data K2 generates third key data K3a by combining the first key data K1a and the second key data K2 received from the server device 3 according to a predetermined rule (S13). Then, it is determined whether or not the third key data K3a has been generated (S14). If the third key data K3a has not been generated (S14: No), the process proceeds to error processing (SE). If the third key data K3a has been generated (S14: Yes), the third key data K3a is transmitted to the communication authentication terminal device 1 (S15).
[0041] Upon receiving the third key data K3a, the communication authentication terminal device 1 writes it to a predetermined location (S16). Next, it determines whether the third key data K3a was successfully written (S17). If the writing was not successful (S17: No), the process proceeds to error processing (SE). If the writing was successful (S17: Yes), the process proceeds to error processing (SE). If the writing was successful (S17: Yes), the third key data K3b generated by the communication authentication terminal device 1 is compared with the third key data K3a received from the mobile wireless terminal 2 to determine whether they match (S18). If the comparison results in a mismatch (S18: No), the process proceeds to error processing (SE). If they match (S18: Yes), the process proceeds to error processing (SE). If they match (S18: Yes), the process transmits information to the mobile wireless terminal 2 confirming that authentication of the mobile wireless terminal 2 has been completed (S19). In addition, a signal indicating that authentication of the mobile wireless terminal 2 has been confirmed is output to a vending machine or the like (S20), and the mobile wireless terminal 2 is handed over to post-authentication processing, such as electronic payment.
[0042] On the other hand, the mobile wireless terminal 2 that has received the information that the authentication has been completed checks whether or not it has received such information (S21). If the completion confirmation has not been received (S21: No), it proceeds to error processing (SE), and if it has been received (S21: Yes), it displays that the authentication has been completed, terminates the authentication operation of the application software, and moves on to the next operation, such as providing a service.
[0043] As described above, the communication authentication terminal device 1 does not require communication with the server device 3, and can be installed and operated without compromising the convenience of NFC. Furthermore, mutual authentication can be performed in a mutual communication system between the communication authentication terminal device 1, the portable wireless terminal 2, and the server device 3. After authentication, electronic payments and various other services can be provided using this mutual communication system. Furthermore, the third key data K3b generated by the communication authentication terminal device 1 is based on the first key data K1b obtained from a source other than the portable wireless terminal 2, and is combined with the second key data K2 independently generated by the communication authentication terminal device 1, thereby enabling more secure communication authentication.
[0044] Although the embodiments of the present invention and modifications based thereon have been described above, the present invention is not necessarily limited to these examples. Furthermore, those skilled in the art will be able to find various alternative embodiments and modifications without departing from the spirit of the present invention or the scope of the appended claims. [Explanation of symbols]
[0045] 1. Communication authentication terminal device 2. Portable wireless terminals 3 Server equipment
Claims
1. A method of communication authentication in a mutual communication system using a server device, a portable wireless terminal connected to the server device, and a communication authentication terminal device communicatively connected to the portable wireless terminal by NFC, comprising: In the portable wireless terminal, a token is transmitted to the server device, and the server device performs token authentication and, upon authentication, receives from the server device first key data K1a generated by a predetermined generation algorithm in the server device, the first key data K1a reflecting the time when the token was transmitted from the portable wireless terminal and the location of the portable wireless terminal at that time, and communicates with the communication authentication terminal device via the NFC; when the communication authentication terminal device establishes a communication connection with the portable wireless terminal via NFC, it creates first key data K1b using the predetermined generation algorithm, reflecting the time when the communication connection with the portable wireless terminal via NFC and the location of the communication authentication terminal device, and returns the created second key data to the portable wireless terminal via NFC; in the portable wireless terminal, upon receiving the second key data, generating third key data by combining the first key data K1a and the second key data received from the server device according to a predetermined rule, and transmitting the third key data to the communication authentication terminal device via the NFC; a communication authentication terminal device that, upon receiving the third key data, combines the generated first key data K1b and the generated second key data in accordance with the predetermined rule, and compares the combined data with the third key data transmitted from the portable wireless terminal to perform communication authentication.
2. 2. The communication authentication method according to claim 1, wherein the portable wireless terminal starts installed application software to transmit the token to the server device, and receives the second key data only when the portable wireless terminal is communicatively connected to the communication authentication terminal device via NFC within a certain period of time after receiving the first key data K1a.
3. 3. The communication authentication method according to claim 1, wherein the second key data is random number data.
4. 4. The method for authenticating communications according to claim 3, wherein the third key data is generated by combining the first key data K1a and the second key data and converting the combined data into a character string of a predetermined number.
5. 5. The method for authenticating communications according to claim 4, wherein the conversion into the character string is performed using a hash function.
Citation Information
Patent Citations
Method for protecting secret file of security measure application
JP2007011556A
Car sharing system
JP2012221224A
Communication device of automatic selling machine
JP2014096090A
Authentication system and authentication method
JP2014238721A
Food and drink delivery device and portable terminal
JP2017174320A